[Snort-sigs] SNORT version lifecycle

waldo kitty wkitty42 at ...3507...
Tue Oct 21 00:09:19 EDT 2014


On 10/20/2014 1:50 PM, Hanson.Webster at ...3973... wrote:
> I found something on line that for that error.
>
> comment out the line in your snort.conf /similar/ to the
> following...
>
> dynamicdetection directory /usr/local/lib/snort_dynamic_rules
>
> just place a # at the beginning of the line and try starting snort again...

that disables your shore object rules... it may or may not be a desirable choice...

> I did this and I get a little further,  now I get this error:
>
> +----------------------------------------------------------------
>
> [ Number of patterns truncated to 20 bytes: 324 ]
>
> pcap DAQ configured to passive.
>
> Acquiring network traffic from "eth0".
>
> ERROR: Can't set DAQ BPF filter to '.T' (pcap_daq_set_filter: pcap_compile:
> illegal char '.')!

please post your complete command line to start your snort... this appears to be 
like many others in which the order of parameters is not correct...

-- 
  NOTE: No off-list assistance is given without prior approval.
        Please *keep mailing list traffic on the list* unless
        private contact is specifically requested and granted.




More information about the Snort-sigs mailing list